California is accelerating independent AI-verification and audit oversight while studying additional frontier-model safeguards—but it has not mandated an AI “kill switch.”
- November 16, 2026
- Recommendations on possible additional AI-safety requirements due to the Governor
- May 1, 2027
- Independent-verification application requirements, procedures, and criteria due
- December 1, 2027
- Specified AI-auditor implementation requirements due
- Under study
- Kill switch — not presently mandated
What Did California Do on September 18?
Governor Gavin Newsom signed Executive Order N-9-26 on September 18, 2026.
The order took effect immediately and directs California’s Government Operations Agency to accelerate implementation of recently enacted AI-oversight requirements.
It also requires the agency, working with the Governor’s Office of Emergency Services and national experts, to recommend possible changes to California’s AI-safety laws.
The order is significant because it moves California’s AI framework from broad policy toward specific implementation deadlines, independent review, auditing, and possible additional safeguards.
But one point requires care: California did not enact a mandatory AI kill switch through this executive order.
The order directs experts to study and recommend whether California law should require one in the future.
What Is Already Required?
The executive order builds on two laws signed on September 9, 2026.
SB 813 created a framework for independent verification organizations capable of assessing AI systems and models for safety and compliance. AB 1405 created a state registry for AI auditors and standards addressing their independence, transparency, and integrity.2
Executive Order N-9-26 does not replace those laws. Instead, it accelerates parts of their implementation.
What Deadlines Did the Executive Order Set?
The order establishes several concrete deadlines.
By May 1, 2027, the Government Operations Agency must complete the requirements identified in Government Code section 8898.1 and publicly post application requirements, procedures, and criteria for independent verification organizations.
By December 1, 2027, the agency must complete specified requirements under Government Code section 11549.82 concerning AI auditors and begin the additional actions required by that statute.
November 16, 2026 is the nearest and potentially most important deadline. By then, the Government Operations Agency, in consultation with the Governor’s Office of Emergency Services and national experts, must submit recommendations concerning possible amendments to California’s AI-safety laws.
What Safeguards Must California Evaluate?
The executive order requires the expert group to consider several possible future requirements.
Those include whether large frontier-AI developers should place designated independent verification organizations onsite to conduct periodic audits and evaluations; obtain independent verification of required safety frameworks, transparency reports, and risk assessments; maintain an emergency shutdown mechanism for frontier models whose effectiveness is independently tested; and operate under expanded definitions of reportable critical safety incidents.
These are subjects for recommendations. They are not all present legal obligations merely because they appear in the executive order.
That distinction matters for businesses trying to determine what they must do today.
Did California Require an AI “Kill Switch”?
No—not yet.
The executive order directs experts to evaluate a possible future requirement for a frontier-model emergency shutdown mechanism. It describes the concept as a “kill switch” and asks officials to consider requiring its effectiveness to be verified on an ongoing basis by an independent verification organization.
But the executive order itself does not directly impose that requirement on AI developers.
A future mandate could require additional legislative, regulatory, or other lawful state action depending on how California chooses to implement the recommendations.
For now, businesses should treat the kill-switch concept as an important policy proposal to monitor—not a present compliance obligation.
Why This Matters for Startups and Technology Companies
The most immediate impact may fall on the largest frontier-model developers. But the broader direction of California regulation also matters to smaller companies that develop AI products, integrate third-party AI models, sell AI-enabled software to enterprise customers, rely on AI vendors, process sensitive information through AI systems, or raise capital based on AI-driven products.
As AI oversight becomes more formal, compliance questions can increasingly affect ordinary business transactions, including vendor agreements, enterprise contracts, representations and warranties, privacy policies, insurance applications, financing or acquisition diligence, security reviews, and risk-allocation provisions.
That does not mean every California startup suddenly faces frontier-model regulation. It means businesses should know which AI systems they use, where those systems come from, and what contractual and regulatory obligations may attach to them. Those questions are part of sound startup and business transactions planning.
Four Different Legal Buckets Businesses Should Keep Separate
First, existing law consists of requirements already enacted by the Legislature and signed into law.
Second, implementation deadlines direct state agencies to move faster on portions of the existing framework.
Third, recommended safeguards—including embedded independent verification organizations and a frontier-model shutdown mechanism—remain under evaluation.
Fourth, some recommendations may eventually become new statutory or regulatory obligations. That has not happened merely because the executive order requested recommendations.
Keeping these categories separate prevents headlines from being mistaken for current legal obligations.
What Should Founders Do Now?
Most businesses do not need to redesign their AI systems tomorrow because of this order. A more practical response is to improve visibility into current AI use.
Founders and management teams should understand what AI tools the company uses; which vendors provide them; what company or customer data those tools receive; what contracts govern their use; whether customers receive representations about AI; who owns AI-assisted output; whether insurance addresses technology-related risks; and whether future state oversight could affect the company’s vendors or products.
Questions about intellectual-property ownership and licensing can also arise when a company relies on AI-assisted output.
A separate Mahrouyan Law Insight discusses AI-generated code and copyright risk.
That information is useful regardless of where California’s next round of AI regulation ultimately lands.
What Happens Next?
The first major development should arrive by November 16, 2026, when the state’s recommendations are due.
Those recommendations should provide greater clarity on whether California intends to pursue additional requirements involving onsite independent verification, third-party verification of safety disclosures, frontier-model shutdown mechanisms, and expanded incident-reporting standards.
The May and December 2027 implementation milestones will then become increasingly important as the existing oversight framework moves into operation.
This article will be updated as those events occur.
The Broader Lesson
California’s September 18 order does not create an immediate universal AI shutdown requirement. Its significance is broader.
The state is moving toward a regulatory model in which independent verification, auditing, documented risk assessment, and external accountability may play an increasingly important role in AI development.3
For businesses, the practical lesson is simple: AI compliance is becoming part of ordinary corporate risk management.
Technology choices may increasingly affect contracts, diligence, insurance, governance, and transactions—not merely engineering decisions.
Footnotes
- Cal. Exec. Order N-9-26 (Sept. 18, 2026) ↩
- Office of Governor Gavin Newsom, “Governor Newsom Signs First-in-the-Nation AI Safeguards to Protect Californians” (Sept. 9, 2026) ↩
- Office of Governor Gavin Newsom, “Governor Newsom Issues Executive Order to Accelerate Independent Oversight and Advance the Creation of an AI Kill Switch” (Sept. 18, 2026) ↩
Sources & Authorities
- Cal. Exec. Order N-9-26 (Sept. 18, 2026) — signed PDF — Primary authority for the order’s effective date, implementation deadlines, recommendation deadline, and safeguards under evaluation.
- Office of Governor Gavin Newsom, “Governor Newsom Signs First-in-the-Nation AI Safeguards to Protect Californians” (Sept. 9, 2026) — Official announcement context for SB 813 and AB 1405.
- Office of Governor Gavin Newsom, “Governor Newsom Issues Executive Order to Accelerate Independent Oversight and Advance the Creation of an AI Kill Switch” (Sept. 18, 2026) — Official public-announcement context; the signed order controls the legal description above.
Mahrouyan Law handles these matters directly. Read more about how the firm approaches startup & business transactions in California, or discuss your own situation with the firm.
Discuss Your Matter
Mahrouyan Law advises founders and businesses on selected startup, technology, intellectual-property, contract, and risk-allocation matters. As California’s AI framework develops, businesses may need to consider how new requirements affect agreements, diligence, governance, and operations.

Omeed Mahrouyan is the founder of Mahrouyan Law, P.C., a California firm handling business and commercial litigation, property and cargo damage claims, personal injury, landlord representation, startup transactions, and practical intellectual property matters. Clients work directly with him on strategy, drafting, and case decisions.
More about Omeed Mahrouyan →
